AI coding agents are pulling packages nobody registered
September 8, 2026. From issue 5 of The Compliance Brief, 2 stories for teams running an ISO 27001 or ISO 42001 management system.
Issue 5 of The Compliance Brief was published on September 8, 2026. 2 of its 5 stories bear on ISO 27001, ISO 42001 and supplier risk, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for teams running an ISO 27001 or ISO 42001 management system.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: Schneier on Security
Researchers scanned 6,214 live domains belonging to defence contractors, Fortune 500 and large tech companies and found 8,265 llms.txt and llms-full.txt files. Of those, 120 on different sites pointed to code packages or domain names that were not registered.
Our take, in short
This is dependency confusion with a new delivery path, and the old defences still apply. Pin your dependencies, keep an internal registry that fails closed on unknown names, and make sure an agent cannot install anything that a human would not have been allowed to install.
Read the full take on traztech.ca
McKesson tells the SEC it was hit through third-party applications
Source: Help Net Security
McKesson disclosed a cybersecurity incident in which attackers got into third-party applications and stole data, with the intrusion detected on August 25, 2026. The SEC filing says the investigation is in its early stages and the company has not determined the incident is material or likely to be material.
Our take, in short
Read that filing from the other side of the table. You are the third-party application in somebody's stack, and when a customer of yours writes their own version of this disclosure, your name goes in it.
Read the full take on traztech.ca
Related on ISO27K
- ISO 42001 readiness check
- AI certification: what can be certified
- ISO 27001 certification cost, itemised
- ISO 27001 checklist, clause by clause
Also in issue 5
Outside ISO 27001, ISO 42001 and supplier risk, but in the same email:
- Thomson Reuters court software breached in March, disclosed in September
- An ID verification vendor appears to be the source of 153 million licence scans
- FTC takes $4.85M from Nuvei over who it let onto its rails
Older: issue 4 All issues on ISO27K Newer: issue 6
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.